Map information management system, map information management device, map company exclusive application data management device, and automotive data management device

ABSTRACT

A map information management system includes a map company exclusive application data management device that confirms data authenticity from encrypted data obtained from a dynamic map data management device and generates encrypted data from added map company exclusive application data to dynamic map data by a map company exclusive secret key, and an automotive data management device that obtains added map company exclusive application data to dynamic map data from the map company exclusive application data management device, confirms data authenticity that is added map company exclusive application data to dynamic map data with using a map company exclusive application data public key, and generates encrypted data from data with automotive company exclusive application data by an automotive company exclusive application data secret key. When providing map information via plural organizations, the map information management system prevents data alteration and confirms data authenticity of the map information.

TECHNICAL FIELD

The present invention relates to a map information management systemmanaging map information.

BACKGROUND ART

With spread of satellite position technology, new industries such asautomatic driving using three-dimensional positioning information androad pricing are considered. In an automatic driving system, researchand development of advanced technology of map information (a dynamicmap) are conducted. The dynamic map is configured by linking each layerinformation including information such as dynamic information (such assurrounding vehicles, pedestrian information, traffic lightinformation), quasi-dynamic information (such as traffic accidentinformation, traffic jam information, narrow area weather information),quasi-static information (such as traffic regulation information, roadconstruction information, wide area weather information) and staticinformation (such as road surface information, traffic lane information,three-dimensional building information). And a maintenance of commoninfrastructure using the three-dimensional positioning informationincluding the dynamic map is promoted (for instance, refer to Non-PatentLiterature 1, Non-Patent Literature 2).

An automatic driving vehicle is mounted with the dynamic map includingan automatic driving map data for a navigation use. Additionally, theautomatic driving vehicle is mounted with a large number of autonomoussensors such as cameras and radars to observe surrounding environment ofthe own vehicle and detect presence or absence of obstacles such as theother vehicles, people and buildings around the own vehicle.

The automatic driving vehicle recognizes current self-location by a mapmatching of self-location information obtained from a vehicle speedpulse (running speed), a yaw rate (azimuth angular speed) and a receivedGPS positioning signal of the own vehicle and the automatic driving mapdata. The automatic driving vehicle predicts future self-locationinformation from the current self-location information (coordinates),the running speed, the azimuth angular speed and the like of the ownvehicle. An automatic driving is conducted by adjusting a driving force,a steering angle, a braking force and the like of the own vehicle by anautonomous control with using sensor information by an autonomous sensormounted on the own vehicle and the self-location information.

In dynamic map including automatic driving map data mounted on theautomatic driving vehicle, an accuracy of the road map needs a highprecision map accuracy (for instance, 1/500 scale) rather than a mapaccuracy of general map data used for a conventional car navigation (forinstance, 1/2500 scale).

Further, by using information on the surrounding road conditionscollected by the autonomous sensors and the dynamic map including theautomatic driving map data in conjunction with each other, the automaticdriving vehicle can determine stops, starts and the like atpredetermined positions on the automatic driving map, while checkingsequentially its own locations on the automatic driving map. Forinstance, at a certain intersection on the automatic driving map data,the automatic driving vehicle receives current traffic light informationof the traffic light from a light beacon, radio beacons such as a 700MHz band side radio device, a 5.8 GHz band side radio device, and thelike. The automatic driving vehicle can recognize a distance from thecurrent self-location to the intersection which the automatic drivingvehicle will pass by, a stop line position, the current signalinformation and the like, and determine stops of the vehicle includingtemporary stops at intersections, the vehicle start timings,intersection passing speed and the like (For instance, refer to PatentLiterature 1).

With respect to the dynamic map including the automatic driving map datamounted on the automatic driving vehicle or a car navigation device,fundamental dynamic map data is generated by a map generating device ofa map information management system, data-provided to a map company oran automotive company via a data output device and stored in the carnavigation device mounted on the automatic driving vehicle. Map dataused in a conventional car navigation device is distributed to carnavigation devices from an information distribution center of the mapcompany, an automotive company or the like via network lines such as amobile phone, a public line and an automotive company exclusive line,and data update is conducted. Against data alteration at the time ofinformation distribution and for ensuring a validity of map data,information security is ensured by an encryption technique using asecret key, a public key and the like (for instance, Patent Literature2).

CITATION LIST Non-Patent Literature

-   Non-Patent Literature 1: Council on Competitiveness-Nippon, Final    Report of Project in Fiscal year 2014 “Service Using Three    Dimensional Location Information and Common Infrastructure    Maintenance”, Council on Competitiveness-Nippon-   Non-Patent Literature 2: Modeling of Driving Environment/Dynamic    Map, Nissan Motor Co., Ltd., SHIRATO Ryota, 29 Jan. 2015,    SIP-adushttp://www8.cao.go.jp/cstp/gaiyo/sip/iinkai/jidousoukou_media/2kai/shiryo4.pdf

Patent Literature

-   Patent Literature 1: JP 2005-250564 A-   Patent Literature 2: JP 2008-175648 A

SUMMARY OF INVENTION Technical Problem

When a map generating device data-provides dynamic map to a map companyand an automotive company, it is necessary to ensure informationsecurity in data transfer between different companies. For instance, amap company which has received dynamic map adds application dataexclusively for a map company (hereafter, map company exclusiveapplication data) to the dynamic map. The map company data-delivers andprovides the dynamic map to which the map company exclusive applicationdata is added to an automotive company. The automotive company addsapplication data exclusively for an automatic company (hereafter,automotive company exclusive application data) such as automatic drivingmap data to the dynamic map data-provided from the map generating deviceof the map company or the dynamic map with the map company exclusiveapplication data and implements the data in a memory device of anautomatic driving car navigation device.

The automotive company that has received data including the dynamic mapis needed to prevent data alternation of the data by an illegal accessand an illegal operation from the outside when incorporating the datainto its own automatic driving vehicle or its own car navigation device.For instance, the automotive company needs to prevent data alternationwhen providing automatic driving vehicles or navigation devices to otherautomotive companies via OEM (Original Equipment Manufacturer)provisions.

Also, when receiving data including dynamic map data and whenimplementing the data in the automatic driving vehicles or thenavigation devices, authenticity certification scheme to confirm that agenerator of the data is not an unauthorized one is necessary.

However, a conventional map information management system does notemploy any measures to prevent alternation of data at a time ofdata-providing the dynamic map via a plurality of companies (a pluralityof organizations) such as the automotive company or the map company andtransferring the data. Moreover, the conventional map informationmanagement system does not employ any scheme to confirm the authenticityof the provided data at a time when implementing the data in automotivesor car navigation devices.

The present invention is made for solving the above-mentioned problem.The present invention aims to obtain a mapping information managementsystem which prevents data alternation of dynamic map data including carcompany exclusive application data such as automatic driving mapinformation and confirms data authenticity of the dynamic map dataincluding the car company exclusive application data such as theautomatic driving map data at a time when the dynamic map data isprovided via a plurality of organizations, the dynamic map dataincluding the car company exclusive application data such as theautomatic driving map information.

Solution to Problem

A map information management system according to the present inventionincludes:

-   -   a dynamic map data management device to generate encrypted data        based on pre-generated dynamic map data being map information,        using a dynamic map data secret key, and output;    -   map company exclusive application data management device to        obtain the encrypted data from the dynamic map data management        device, confirm authenticity of the dynamic map data, using a        pre-received dynamic map data public key corresponding to the        dynamic map data secret key and the encrypted data obtained from        the dynamic map data management device, generate encrypted data        by a pre-received map company exclusive application data secret        key, based on data which is obtained by adding map company        exclusive application data to the dynamic map data which has        been confirmed to be authentic, and output the data which is        obtained by adding the map company exclusive application data to        the dynamic map data which has been confirmed to be authentic;        and    -   an automotive data management device to obtain the data which is        obtained by adding the map company exclusive application data to        the dynamic map data from the map company exclusive application        data management device, confirm authenticity of the data which        is obtained by adding the map company exclusive application data        to the dynamic map data, using a pre-received map company        exclusive application data public key corresponding to the map        company exclusive application data secret key and the encrypted        data, and generate encrypted data to be implemented in a        vehicle, by a pre-received automotive company exclusive        application data secret key, based on data which is further        obtained by adding automotive company exclusive application data        to the data which is obtained by adding the map company        exclusive application data to the dynamic map data which has        been confirmed to be authentic.

Advantageous Effects of Invention

According to the present invention, it is possible to obtain a mapinformation system which prevents data alternations of map informationand confirm data authenticity of the map information at the time whenthe map information is provided via a plurality of organizations.

BRIEF DESCRIPTION OF DRAWINGS

FIG. 1 is a diagram illustrating a configuration of a map informationmanagement system according to Embodiment 1.

FIG. 2 is a diagram illustrating a configuration of dynamic map datamanagement device of the map information management system according toEmbodiment 1.

FIG. 3 is a flowchart illustrating a flow of a map company exclusiveapplication data management device and an automotive company exclusiveapplication data management device of the map information managementsystem according to Embodiment 1.

FIG. 4 is a diagram illustrating a configuration of the dynamic map datamanagement device of the map information management system according toEmbodiment 2.

FIG. 5 is a flowchart illustrating a flow of the map company exclusiveapplication data management device and the automotive company exclusiveapplication data management device of the map information managementsystem according to Embodiment 1.

EMBODIMENT 1

FIG. 1 illustrates a configuration of a map information managementsystem according to Embodiment 1 of the present invention. In FIG. 1,the map information management system includes a dynamic map datamanagement device 11, a map company exclusive application datamanagement device 12, and an automotive company exclusive applicationdata management device 13. The dynamic map data management device 11 isa common infrastructure to manage basic map information. The map companyexclusive application data management device 12 is operated and managedby, for instance, a map company. The automotive company exclusiveapplication data management device 13 is operated and managed by, forinstance, an automotive company. An external organization datamanagement device 10 is a device providing original data which is usedwhen the dynamic map data is generated by the dynamic map datamanagement device 11. The dynamic map data management device 11 receivesvarious sorts of information as the original data for generating thedynamic map, from the external organization data management device 10. Avehicle 15 is an automatic driving vehicle or a vehicle on which a carnavigation device is mounted.

The external organization data management device 10 includes one or aplurality of servers, and stores various sorts of information each ofwhich is possessed by a nation, local governments, road utilities suchas expressway companies, road traffic information communication systemcenters, non-governmental organizations (common infrastructuremaintenance organizations) such as Japan Traffic Information Center, andthe like. The various sorts of information as the original data forgenerating the dynamic map include traffic management information suchas traffic light displays and traffic regulations, traffic conditioninformation such as vehicles and pedestrians, traffic road environmentalinformation such as pavement sign displays, road signs and surroundingconstructions, detailed road management information such as weatherinformation, road shapes, road surface conditions, traffic constructionpoints, and the like. Traffic road environmental information includestwo-dimensional road linear information, three-dimensional point groupinformation which discretely represents three-dimensional positioningcoordinates of a road surface or a surface shape of surrounding objectson a road, and the like.

At this point, the three-dimensional point group information includeshigh accuracy three-dimensional position information in sub meter orcentimeter order measured by, for instance, MMS (Mobile Map System; highaccuracy GPS movement measurement device). Using a vehicle high accuracyposition and a position control, and a high accuracy laser radar and ahigh accuracy camera, MMS measures three-dimensional positioninginformation of the roads and the surrounding objects by overlappingcamera image data and laser point group data. The three-dimensionalpositioning accuracy of the laser point group obtained by MMS isregarded that an absolute accuracy of latitude, longitude and height is10 cm, for instance. By using a high accurate positioning receiveravailable for quasi-zenith satellite positioning service, the MMS iscapable of conducting a high accurate positioning by GNSS signals suchas GPS signal and positioning reinforcement signals delivered from thequasi-zenith satellite.

The dynamic map data management device 11 generates dynamic map data 1which is an original drawing of map information based on the varioussorts of information mentioned above from the external organization datamanagement device 10. The dynamic map data management device 11generates encrypted data 100 which is encrypted dynamic map data 1generated that is mentioned above by using a dynamic map data secret key501, outputs the encrypted data 100 to each of the map company exclusiveapplication data management device 12 and the automotive companyexclusive application data management device 13.

The map company exclusive application data management device 12pre-receives a dynamic map data public key 502 corresponding to thedynamic map data secret key 501 and confirms an authenticity of theencrypted data 100 from the dynamic map data management device 11. Themap company exclusive application data management device 12 adds the mapcompany exclusive application data 2 as map information to the dynamicmap data 1 included in the encrypted data 100 whose authenticity hasbeen confirmed. Then, the map company exclusive application datamanagement device 12 generates an encrypted data 110 by a map companyexclusive application data secret key 503. The map company exclusiveapplication data management device 12 outputs the encrypted data 110 tothe automotive company exclusive application data management device 13.

The automotive company exclusive application data management device 13pre-receives the dynamic map data public key 502 corresponding to thedynamic map data secret key 501 and confirms the authenticity of theencrypted data 100 from the dynamic map data management device 11. Theautomotive company exclusive application data management device 13 addsthe automotive company exclusive application data 3 as map informationto the dynamic map data 1 that is owned by the encrypted data 100 whoseauthenticity has been confirmed, and generates encrypted data 120 by anautomotive company exclusive application data secret key 505. Theautomotive company exclusive application data management device 13implements the encrypted data 120 and the encrypted data 110 on thevehicle 15. The vehicle 15 pre-receives an automotive company exclusiveapplication data public key 506 corresponding to the automotive companyexclusive application data secret key 505, and confirms the authenticityof the encrypted data 120 and the encrypted data 110.

Also, the automotive company exclusive application data managementdevice 13 pre-receives a map company exclusive application data publickey 504 corresponding to the map company exclusive application datasecret key 503 and confirms an authenticity of the encrypted data 110from the map company exclusive application data management device 12.The automotive company exclusive application data management device 13adds the automotive company exclusive application data 3 as mapinformation to the dynamic map data 1 and the map company exclusiveapplication data 2 which are owned by the encrypted data 110 whoseauthenticity has been confirmed, and generates encrypted data 130 by theautomotive company exclusive application data secret key 505. Theautomotive company exclusive application data management device 13implements the encrypted data 130 on the vehicle 15. The vehicle 15pre-receives the automotive company exclusive application data publickey 506 corresponding to the automotive company exclusive applicationdata secret key 505, and confirms the authenticity of the encrypted data130. The automotive company exclusive application data 3 is, forinstance, map data for automatic driving.

In this manner, in the map information management system according toEmbodiment 1, data is provided to the vehicle 15 and the like, whileeach data of the dynamic map data 1, the map company exclusiveapplication data 2 and the automotive company exclusive application data3 is kept encrypted, using a public key encryption multiplexing methodwhere data that passes through each of the dynamic map data managementdevice 11, the map company exclusive application data management device12, and the automotive company exclusive application data managementdevice 13 is subsequently encrypted stepwisely.

FIG. 2 illustrates a configuration of the dynamic map data managementdevice 11 of the map information management system according toEmbodiment 1. In FIG. 2, the dynamic map data management device 11includes a dynamic map generating device 111, a dynamic mapcertification authority 112, and a dynamic map data output device 113.The dynamic map generating device 111 and the dynamic map data outputdevice 113 may be composed of the same server or different serversconnected to a network. Also, the dynamic map certification authority112 is installed in a server set outside of a server which includes thedynamic map generating device 111 or the dynamic map data output device113 in the dynamic map data management device 11. Hence, in order tosecure strength of security, the dynamic map certification authority 112is preferably operated and managed separately from the dynamic mapgenerating device 111 and the dynamic map data output device 113.

The dynamic map generating device 111 receives various sorts ofinformation as the original data being used when the dynamic map isgenerated, from the external organization data management device 10. Thedynamic map generating device 111 is a map generating device generatingthe dynamic map data 1 based on the various sorts of information as theoriginal data being used when the dynamic map is generated, obtainedfrom the external organization data management device 10.

The dynamic map certification authority 112 generates a plurality ofsecret keys and a plurality of public keys 150, stores managers, usersand renewal dates and time of the generated secret keys and public keys,and conducts renewal managements.

For instance, the dynamic map certification authority 112 generates eachof the dynamic map data secret key 501 and the dynamic map data publickey 502 (502 a, 502 b) for a signature verification of an electronicsignature by the dynamic map data secret key 501, the map companyexclusive application data secret key 503 and the map company exclusiveapplication data public key 504 for a signature verification of anelectronic signature by the map company exclusive application datasecret key 503, and the automotive company exclusive application datasecret key 505 and the automotive company exclusive application datapublic key 506 for a signature verification of an electronic signatureby the automotive company exclusive application data secret key 505, asthe plurality of secret keys and the plurality of public keys 150.

The dynamic map certification authority 112 delivers each of theplurality of secret keys generated and the plurality of public keys 150generated to a corresponding and appropriate destination among the mapcompany exclusive application data management device 12, the automotivecompany exclusive application data management device 13, and the vehicle15 using an encrypted communication via a communication network, while asecurity is being maintained.

For instance, the dynamic map data public key 502 is delivered to eachof the map company exclusive application data management device 12 andthe automotive company exclusive application data management device 13.The map company exclusive application data secret key 503 is solelydelivered to the map company exclusive application data managementdevice 12. The map company exclusive application data public key 504 isdelivered to the automotive company exclusive application datamanagement device 13. The automotive company exclusive application datasecret key 505 is solely delivered to the automotive company exclusiveapplication data management device 13. The automotive company exclusiveapplication data public key 506 is delivered to the automotive companyexclusive application data management device 13 and the vehicle 15.

Here, it is possible to treat the dynamic map data public key 502 thatthe map company exclusive application data management device 12 receivesas a dynamic map data public key 502 a, and treat the dynamic map datapublic key 502 that the automotive company exclusive application datamanagement device 13 receives as a dynamic map data public key 502 b, soas to have a different access right, a different decrypting right, adifferent data processing right and the like between the keys.

Further, the dynamic map certification authority 112 may encrypt theplurality of secret keys and the plurality of public keys 150 and storethem in electronic mediums such as a DVD-ROM, a BD-ROM or a USB memory.The electronic mediums such as the DVD-ROM, the BD-ROM or the USB memoryare preferably delivered to each of the map company exclusiveapplication data management device 12 and the automotive companyexclusive application data management device 13.

The dynamic map data output device 113 generates a dynamic map dataelectronic signature 95 which is encrypted data (data signature 1) forconducting an authenticity certification of the dynamic map data, usingthe dynamic map data secret key 501, generated based on the dynamic mapdata 1 in a predetermined unit (a predetermined length of bit array or avariable length of bit array) generated by the dynamic map generatingdevice 111. For instance, the dynamic map data output device 113 outputsthe dynamic map data electronic signature 95 by inputting the dynamicmap data 1 and the dynamic map data secret key 501 into a signaturegenerating algorithm.

Also, the dynamic map data output device 113 adds to the generateddynamic map data 1 in the predetermined unit the dynamic map dataelectronic signature 95 corresponding to the dynamic map data 1, andgenerates the encrypted data 100 which is packetized data obtained bycombining the dynamic map data 1 and the dynamic map data electronicsignature 95. The encrypted data 100 here may be a plain text in whichthe contents of the dynamic map data 1 and the dynamic map dataelectronic signature 95 can be browsed, and is referred to as encrypteddata in a meaning that a signature verification of the dynamic map data1 can be carried out by using the dynamic map data electronic signature95.

The dynamic map data output device 113 outputs the encrypted data 100 toeach of the map company exclusive application data management device 12and the automotive company exclusive application data management device13.

The dynamic map data output device 113 may store the encrypted data 100after an encryption in the electronic mediums such as a DVD-ROM, aBD-ROM, or a USB memory, and may deliver the electronic mediums such asthe DVD-ROM, the BD-ROM, or the USB memory to each of the map companyexclusive application data management device 12 and the automotivecompany exclusive application data management device 13.

FIG. 3 is a diagram illustrating a data processing flow by the mapcompany exclusive application data management device 12 and theautomotive company exclusive application data management device 13 inthe map information management system according to Embodiment 1. In FIG.3, the vehicle 15 is an automatic driving vehicle with a memory device,a car navigation device including a memory device and a map displaydevice, or the like.

In FIG. 3, the map company exclusive application data management device12 obtains the dynamic map data public key 502 (502 a) and the mapcompany exclusive application data secret key 503 from the dynamic mapdata management device 11 by the encrypted communication via thecommunication network. Further, the map company exclusive applicationdata management device 12 receives the encrypted data 100 in which thedynamic map data 1 and the dynamic map data electronic signature 95 arecombined, from the dynamic map data management device 11 by theencrypted communication via the communication network.

Note that the map company exclusive application data management device12 and the automotive company exclusive application data managementdevice 13 may receive the encrypted data 100 in a state that theencrypted data 100 is stored in the electronic mediums such as theDVD-ROM, the BD-ROM or the USB memory.

When acquiring the encrypted data 100, the map company exclusiveapplication data management device 12 conducts the signatureverification of the dynamic map data 1 using the dynamic map data publickey 502 (502 a) and the dynamic map data electronic signature 95, at thesame time as the acquisition, at the predetermined time interval, orafter a predetermined time period has lapsed. Then, the map companyexclusive application data management device 12 confirms theauthenticity of the dynamic map data 1 in the encrypted data 100. Forinstance, by inputting the dynamic map data 1, the dynamic map dataelectronic signature 95 and the dynamic map data public key 502 (502 a)in the encrypted data 100 into the signature verification algorithm, themap company exclusive application data management device 12 inspectswhether the dynamic map data 1 is a legitimate (authentic) one receiveddirectly or indirectly from a legitimate generator, and if it islegitimate, the map company exclusive application data management device12 confirms that the dynamic map data 1 is authentic.

After conducting the authenticity certification by the above signatureverification, the map company exclusive application data managementdevice 12 adds the map company exclusive application data 2 to thedynamic map data 1 which is confirmed (guaranteed) to be authentic so asto generate combination data 105.

The map company exclusive application data 2 includes, for instance,information on shops, information on architectures such as buildings andresidences, information on public facilities such as parks andlibraries, information of commercial facilities such as amusement parksand shopping malls, around roads. The map company exclusive applicationdata 2 is map company exclusive application data including informationon names, addresses, telephone numbers, three-dimensional model shapes,exits and entrances of each of shops, architectures, and facilities.

Based on the dynamic map data electronic signature 95 and the dynamicmap data 1 to which the map company exclusive application data 2 isadded, the map company exclusive application data management device 12generates a map company exclusive application data electronic signature114 using the map company exclusive application data secret key 503. Themap company exclusive application data electronic signature 114 isencrypted data (data signature 1•2) for conducting the authenticitycertification of the dynamic map data electronic signature 95 and thedynamic map data 1 to which the map company exclusive application data 2is added. For instance, the map company exclusive application datamanagement device 12 outputs the map company exclusive application dataelectronic signature 114 by inputting the dynamic map data 1, thedynamic map data electronic signature 95 and the map company exclusiveapplication data secret key 503 into the signature generating algorithm.

The map company exclusive application data management device 12generates the encrypted data 110 which is packetized data obtained bycombining the dynamic map data 1, the map company exclusive applicationdata 2, the dynamic map data electronic signature 95 and the map companyexclusive application data electronic signature 114. The encrypted data110 here may be a plain text in which the contents of the dynamic mapdata 1, the map company exclusive application data 2, the dynamic mapdata electronic signature 95 and the map company exclusive applicationdata electronic signature 114 can be independently browsed, and isreferred to as encrypted data in a meaning that signature verificationsof the dynamic map data 1 and the map company exclusive application data2 can be carried out by using the map company exclusive application dataelectronic signature 114.

The map company exclusive application data management device 12 outputsthe encrypted data 110 to the automotive company exclusive applicationdata management device 13.

In FIG. 3, the automotive company exclusive application data managementdevice 13 obtains the dynamic map data public key 502 (502 b) and themap company exclusive application data secret key 503 from the dynamicmap data management device 11 by the encrypted communication via thecommunication network. Further, the automotive company exclusiveapplication data management device 13 receives the encrypted data 100 inwhich the dynamic map data 1 and the dynamic map data electronicsignature 95 are combined, from the dynamic map data management device11 by the encrypted communication via the communication network.

Note that the map company exclusive application data management device12 and the automotive company exclusive application data managementdevice 13 may receive the encrypted data 100 in a state that theencrypted data 100 is stored in the electronic mediums such as theDVD-ROM, the BD-ROM or the USB memory.

When acquiring the encrypted data 100, the automotive company exclusiveapplication data management device 13 conducts the signatureverification of the dynamic map data 1 using the dynamic map data publickey 502 (502 b) and the dynamic map data electronic signature 95 toconfirm the authenticity of the dynamic map data 1 in the encrypted data100, at predetermined time.

After conducting the authenticity certification of the dynamic map data1 by the above signature verification, the automotive company exclusiveapplication data management device 13 adds the automotive companyexclusive application data 3 to the dynamic map data 1 which isconfirmed (guaranteed) to be authentic so as to generate combinationdata 115.

The automotive company exclusive application data 3 is information onvicinities of road used by vehicles. For instance, the automotivecompany exclusive application data 3 is automotive company exclusiveapplication data including a point where a vehicle should deceleratebefore entering a curve on the road and an entry speed at that point, apoint where a right turning vehicle should decelerate and an entry speedat the point on a right turning traffic lane of a road, a position anddetails of traffic lights and road signs, puddles on a road, thepresence or the absence of freezing or piled-up snow, a traffic jamcondition of a road, a road construction area, and the like.

Based on the dynamic map data electronic signature 95 and thecombination data 115 with the dynamic map data 1 to which the automotivecompany exclusive application data 3 is added, the automotive companyexclusive application data management device 13 generates an automotivecompany exclusive application data electronic signature 121 using theautomotive company exclusive application data secret key 505. Theautomotive company exclusive application data electronic signature 121is encrypted data (data signature 1.3) for conducting the authenticitycertifications of the dynamic map data electronic signature 95 and thedynamic map data 1 to which the automotive company exclusive applicationdata 3 is added. The automotive company exclusive application datamanagement device 13 generates the encrypted data 120 which ispacketized data obtained by combining the dynamic map data 1, theautomotive company exclusive application data 3, the dynamic map dataelectronic signature 95 and the automotive company exclusive applicationdata electronic signature 121. The encrypted data 120 here may be aplain text in which the contents of the dynamic map data 1, theautomotive company exclusive application data 3, the dynamic map dataelectronic signature 95 and the automotive company exclusive applicationdata electronic signature 121 can be independently browsed, and isreferred to as encrypted data in a meaning that signature verificationsof the dynamic map data 1 and the automotive company exclusiveapplication data 3 can be carried out by using the automotive companyexclusive application data electronic signature 121.

The automotive company exclusive application data management device 13delivers the encrypted data 120 to the memory device of the vehicle 15using the encrypted communication via the communication network.

The automotive company exclusive application data management device 13may store the encrypted data 120 after the encryption in the electronicmediums such as a DVD-ROM, a BD-ROM or a USB memory, and may data-storein the electronic mediums such as the DVD-ROM, the BD-ROM or the USBmemory in the memory device of the vehicle 15 or the car navigationdevice via the electronic medium reading device of the vehicle 15 or thecar navigation device (for instance, a DVD reader).

Also, in FIG. 3, the automotive company exclusive application datamanagement device 13 obtains the map company exclusive application datapublic key 504 and the automotive company exclusive application datasecret key 505 from the dynamic map data management device 11 by theencrypted communication via the communication network. Further, theautomotive company exclusive application data management device 13receives the encrypted data 110 in which the dynamic map data 1, the mapcompany exclusive application data 2, the dynamic map data electronicsignature 95 and the map company exclusive application data electronicsignature 114 are combined, from the map company exclusive applicationdata management device 12 by the encrypted communication via thecommunication network.

Note that the automotive company exclusive application data managementdevice 13 may receive the encrypted data 110 in a state that theencrypted data 110 is stored in the electronic mediums such as theDVD-ROM, the BD-ROM or the USB memory.

When acquiring the encrypted data 110, the automotive company exclusiveapplication data management device 13 conducts the signatureverifications of the dynamic map data 1 and the map company exclusiveapplication data 2 using the map company exclusive application datapublic key 504 to confirm the authenticity of the dynamic map data 1 andthe map company exclusive application data 2 in the encrypted data 110,at predetermined time.

After conducting the authenticity certification by the above signatureverification, the automotive company exclusive application datamanagement device 13 adds the automotive company exclusive applicationdata 3 to the dynamic map data 1 and the map company exclusiveapplication data 2 which are confirmed to be authentic so as to generatecombination data 125.

Based on the combination data 125 of the dynamic map data 1 and the mapcompany exclusive application data 2, the dynamic map data electronicsignature 95 and the map company exclusive application data electronicsignature 114 to which the automotive company exclusive application data3 is added, the automotive company exclusive application data managementdevice 13 generates an automotive company exclusive application dataelectronic signature 131 using the automotive company exclusiveapplication data secret key 505. The automotive company exclusiveapplication data electronic signature 131 is encrypted data (datasignature 1•2•3) for conducting the authenticity certifications of themap company exclusive application data 2, the dynamic map dataelectronic signature 95, the map company exclusive application dataelectronic signature 114, and the dynamic map data 1 to which theautomotive company exclusive application data 3 is added.

The automotive company exclusive application data management device 13generates the encrypted data 130 which is packetized data obtained bycombining the dynamic map data 1, the map company exclusive applicationdata 2, the automotive company exclusive application data 3, the dynamicmap data electronic signature 95, the map company exclusive applicationdata electronic signature 114 and the automotive company exclusiveapplication data electronic signature 131. The encrypted data 130 heremay be a plain text in which the contents of the dynamic map data 1, themap company exclusive application data 2, the automotive companyexclusive application data 3, the dynamic map data electronic signature95, the map company exclusive application data electronic signature 114and the automotive company exclusive application data electronicsignature 131 can be independently browsed, and is referred to asencrypted data in a meaning that signature verifications of the dynamicmap data 1, the map company exclusive application data 2 and theautomotive company exclusive application data 3 can be carried out byusing the automotive company exclusive application data electronicsignature 131.

In the encrypted data 130, the map company exclusive application dataelectronic signature 114 may be omitted because an authenticitycertification of the map company exclusive application data 2 can beconducted with the automotive company exclusive application dataelectronic signature 131. That is, the automotive company exclusiveapplication data management device 13 may generate the encrypted data130 which is packetized data in which the dynamic map data 1, the mapcompany exclusive application data 2, the automotive company exclusiveapplication data 3, the dynamic map data electronic signature 95 and theautomotive company exclusive application data electronic signature 131are combined.

The automotive company exclusive data management device 13 delivers theencrypted data 110, the encrypted data 120 and the encrypted data 130 tothe memory device of the vehicle 15 or the car navigation device by theencrypted communication via the communication network. After receivingthe encrypted data 110, the encrypted data 120 and the encrypted data130, the vehicle 15 conducts a signature verification on each of thedynamic map data 1, the map company exclusive application data 2 and theautomotive company exclusive application data 3 using the pre-receivedautomotive company exclusive application data public key 506 receivedbeforehand from the dynamic map certification authority 112 of thedynamic map data management device 11 and confirms the authenticity ofeach data.

The automotive company exclusive application data management device 13may store the encrypted data 110, the encrypted data 120 and theencrypted data 130 after the encryptions in the electronic mediums suchas a DVD-ROM, a BD-ROM or a USB memory, and may data-store in theelectronic mediums such as the DVD-ROM, the BD-ROM or the USB memory inthe memory device of the vehicle 15 or the car navigation device via theelectronic medium reading device of the vehicle 15 or the car navigationdevice (for instance, a DVD reader).

In this manner, in the map information management system according toEmbodiment 1, the dynamic map data management device 11 generates thedynamic map data 1, using data obtained from the external organizationdata management device 10. Then, the dynamic map data management device11 provides data in such a way that the dynamic map data is accompaniedby an electronic signature which has been generated by an encryptionalgorithm, when the dynamic map data 1 is delivered to a plurality oforganizations such as a map company and an automotive company. Thereby,it is possible to prevent data alteration of the dynamic map. Further,it is possible to guarantee that the dynamic map data 1 received by aplurality of organizations such as the map company exclusive applicationdata management device 12 of the map company and the automotive companyexclusive application data management device 13 of the automotivecompany is data from a legitimate data generator or not (it is possibleto confirm the authenticity).

As mentioned above, the map information management system according toEmbodiment 1 includes a dynamic map data management device 11 whichgenerates encrypted data 100 in which a dynamic map data electronicsignature 95 which is encrypted data based on pre-generated dynamic mapdata 1 is added to the dynamic map data 1, using a dynamic map datasecret key 501, and outputs, a map company exclusive application datamanagement device 12 which obtains the encrypted data 100 from thedynamic map data management device 11, confirms authenticity of thedynamic map data 1, using a pre-received dynamic map data public key 502corresponding to the dynamic map data secret key 501 and the encrypteddata 100 obtained from the dynamic map data management device 11,generates a map company exclusive application data electronic signature114 which is encrypted data by a pre-received map company exclusiveapplication data secret key 503, based on data 105 which is obtained byadding map company exclusive application data 2 to the dynamic map data1 which has been confirmed to be authentic, and outputs encrypted data110 which is obtained by adding the map company exclusive applicationdata 2 and the map company exclusive application data electronicsignature 114 to the dynamic map data 1 which has been confirmed to beauthentic, and an automotive company exclusive application datamanagement device 13 which obtains the encrypted data 110 which isobtained by adding the map company exclusive application data 2 to thedynamic map data 1 from the map company exclusive application datamanagement device 12, confirms authenticity of the encrypted data 110which is obtained by adding the map company exclusive application data 2to the dynamic map data 1, using a pre-received map company exclusiveapplication data public key 504 corresponding to the map companyexclusive application data secret key 503, and generates an automotivecompany exclusive application data electronic signature 131 which isencrypted data to be implemented in a vehicle, by a pre-receivedautomotive company exclusive application data secret key 505, based onencrypted data 130 which is further obtained by adding automotivecompany exclusive application data 3 to the data which is obtained byadding the map company exclusive application data 2 to the dynamic mapdata 1 which has been confirmed to be authentic.

Furthermore, a dynamic map data management device 11 includes a dynamicmap generating device 111 which generates the dynamic map data 1, adynamic map certification authority 112 which generates each of adynamic map data secret key 501 and a dynamic map data public key 502(502 a) for a signature verification of an electronic signature by thedynamic map data secret key 501, a map company exclusive applicationdata secret key 503 and a map company exclusive application data publickey 504 for a signature verification of an electronic signature by themap company exclusive application data secret key 503, and an automotivecompany exclusive application data secret key 505 and an automotivecompany exclusive application data public key 506 for a signatureverification of an electronic signature by the automotive companyexclusive application data secret key 505, and distributes eachgenerated secret key and each generated public key, and a dynamic mapdata output device 113 which generates a dynamic map data electronicsignature 95 for conducting an authenticity certification of the dynamicmap data 1, using the generated dynamic map data secret key 501, basedon the generated dynamic map data 1, and outputs the generated dynamicmap data 1 and the dynamic map data electronic signature 95 incombination.

Furthermore, the map company exclusive application data managementdevice 12 obtains the dynamic map data public key 502 (502 a), the mapcompany exclusive application data secret key 503, the dynamic map data1 and the dynamic map data electronic signature 95 from the dynamic mapdata management device 11, conducts a signature verification of thedynamic map data 1, using the dynamic map data public key 502 (502 a)and the dynamic map data electronic signature 95, adds the map companyexclusive application data 2 to the dynamic map data 1 which has beenconfirmed to be authentic by the signature verification, generates a mapcompany exclusive application data electronic signature 114 forconducting an authenticity certification of the dynamic map data 1 towhich the map company exclusive application data 2 has been added, usingthe map company exclusive application data secret key 503, based on thedynamic map data 1 to which the map company exclusive application data 2has been added and the dynamic map data electronic signature 95, andoutputs the dynamic map data 1 to which the map company exclusiveapplication data 2 has been added, the dynamic map data electronicsignature 95 and the map company exclusive application data electronicsignature 114 in combination.

Furthermore, an automotive company exclusive application data managementdevice 13 obtains the map company exclusive application data public key504 and the automotive company exclusive application data secret key 505from the dynamic map data management device 11, obtains the dynamic mapdata 1 to which the map company exclusive application data 2 has beenadded, the dynamic map data electronic signature 95 and the map companyexclusive application data electronic signature 114 from the map companyexclusive application data management device 12, conducts a signatureverification of the dynamic map data 1 to which the map companyexclusive application data 2 has been added, using the map companyexclusive application data public key 504 and the map company exclusiveapplication data electronic signature 114, adds the automotive companyexclusive application data 3 to the dynamic map data 1 to which the mapcompany exclusive application data 2 has been added, which has beenconfirmed to be authentic by the signature verification, generates a mapcompany exclusive application data electronic signature 114 forconducting an authenticity certification of the dynamic map data 1 towhich the automotive company exclusive application data 3 and the mapcompany exclusive application data 2 have been added, using theautomotive company exclusive application data secret key 505, based onthe dynamic map data 1 to which the automotive company exclusiveapplication data 3 and the map company exclusive application data 2 havebeen added and the map company exclusive application data electronicsignature 114, and outputs the dynamic map data 1 to which theautomotive company exclusive application data 3 has been added, the mapcompany exclusive application data 2, the dynamic map data electronicsignature 95 and the automotive company exclusive application dataelectronic signature 131 in combination.

By this way, when providing the map information including the dynamicmap data 1, the map company exclusive application data 2, the automotivecompany exclusive application data 3 and the like via a plurality oforganizations such as a map company and an automotive company insequence, the map information management system according to Embodiment1 prevents data alteration of the map information and conducts theauthenticity certification of the map information.

For instance, data generated in the map company exclusive applicationdata management device 12 of a map company is transmitted to theautomotive company exclusive application data management device 13 of anautomotive company in a state that the dynamic map data electronicsignature 95 and the map company exclusive application data electronicsignature 114 are attached to the data. The automotive company may usethe map information (the dynamic map data 1 and the map companyexclusive application data 2) from the map company without anymodifications, or may use the map information after mounting theautomotive company exclusive application data 3 on it. In a case wherethe automotive company exclusive application data is mounted, thedynamic map data electronic signature 95, and the map company exclusiveapplication data electronic signature 114 or the automotive companyexclusive application data electronic signature 131 are attached, thenthe security of data mounted is guaranteed. In this way, the dataguarded with a security protection by encryption for a purpose ofpreventing alternations of map information including the dynamic mapdata 1 can be stored in the automatic driving vehicle or the carnavigation device.

EMBODIMENT 2

As with the explanations of FIG. 1, the map information system accordingto Embodiment 2 of the present invention includes a dynamic map datamanagement device 11 to which various sorts of information is input froman external organization data management device 10, a map companyexclusive application data management device 12 which is provided withdata from the dynamic map data management device 11, and an automotivecompany exclusive application data management device 13 which isprovided with data from the dynamic map data management device 11 andthe map company exclusive application data management device 12. Avehicle 15 is an automatic driving vehicle or a vehicle on which a carnavigation device is mounted.

In the map information management system according to Embodiment 2, eachof the dynamic map data management device 11, the map company exclusiveapplication data management device 12 and the automotive companyexclusive application data management device 13 conducts an encryptionor a decryption of data according to a homomorphic encryption or a fullyhomomorphic encryption. The homomorphic encryption or the fullyhomomorphic encryption can grant access rights, decrypting rights, anddata processing rights. When a decrypting right is owned, a decryptingcan be conducted, using an allowed public key. Also, when a dataprocessing right is owned, a calculation of the encrypted data whichremains encrypted and additional data can be conducted, using an allowedpublic key.

FIG. 4 is a diagram illustrating a configuration of the dynamic map datamanagement device 11 of the map information management system accordingto Embodiment 2. In FIG. 4, the dynamic map data management device 11includes a dynamic map generating device 111, a dynamic mapcertification authority 112 and a dynamic map data output device 113.The dynamic map generating device 111 and the dynamic map data outputdevice 113 may be composed of the same server or different serversconnected to a network. Also, the dynamic map certification authority112 is installed in a server set outside of the server which composes ofthe dynamic map generating device 111 or the dynamic map data outputdevice 113 in the dynamic map data management device 11. That is, inorder to secure the strength of security, dynamic map certificationauthority 112 is preferably operated and managed separately from thedynamic map generating device 111 and the dynamic map data output device113.

The dynamic map generating device 111 receives various sorts ofinformation from the external organization data management device 10.The dynamic map generating device 111 generates the dynamic map data 1based on the various sorts of information which are obtained from theexternal organization data management device 10.

The dynamic map certification authority 112 according to Embodiment 2generates a plurality of secret keys and a plurality of public keys 150,stores an access right, a decrypting right, a data processing right andrenewal dates and the like of each of the generated secret keys andpublic keys 150, and conducts renewal management. For instance, thedynamic map certification authority 112 generates each of a dynamic mapdata secret key 501, a dynamic map data public key 502 a and a dynamicmap data public key 502 b, a map company exclusive application datasecret key 503, a map company exclusive application data public key 504,an automotive company exclusive application data secret key 505 and anautomotive company exclusive application data public key 506 as theplurality of secret keys and the plurality of public keys 150.

The dynamic map data secret key 501 is used for the encryption of dataaccording to the homomorphic encryption or the fully homomorphicencryption. All rights of access rights, decrypting rights and dataprocessing rights of the dynamic map data secret key 501 are grantedonly to an operator of the dynamic map data output device 113.

Also, the dynamic map data public keys 502 a and 502 b are used for thedecryptions of the encrypted data according to the homomorphicencryptions or the fully homomorphic encryptions using the dynamic mapdata secret key 501. All rights of access rights, decrypting rights anddata processing rights of the dynamic map data public keys 502 a and 502b are granted only to the dynamic map data management device 11.

Besides, access rights and decrypting rights using the dynamic map datapublic key 502 a are granted to the map company exclusive applicationdata management device 12.

Further, access rights, decrypting rights and data processing rightsonly for some type of data using the dynamic map data public key 502 b,are granted to the automotive company exclusive application datamanagement device 13.

Here, the some type of data for which the data processing rights aregranted to the dynamic map data public key 502 b includes, for instance,positions of traffic lights, positions of signs, positions of road signsand the like. Furthermore, other type of data than the some type ofdata, for which the data processing rights are not granted to thedynamic map data public key 502 b includes, for instance, current signinformation of traffic lights, legal display contents of signs and roadsigns, and the like.

Moreover, as the dynamic map data public key 502 a corresponding to thedynamic map data secret key 501 used by the map company exclusiveapplication data management device 12 and the dynamic map data publickey 502 b corresponding to the dynamic map data secret key 501 used bythe automotive company exclusive application data management device 13,it is preferable to use different public keys in order to grantdifferent data processing rights. However, the same public key may beused when the same data processing right is granted.

The map company exclusive application data secret key 503 is used forthe encryption of data according to the homomorphic encryption or thefully homomorphic encryption. All rights of access rights, decryptingrights and data processing rights of the map company exclusiveapplication data secret key 503 are granted only to an operator of themap company exclusive application data management device 12.

The map company exclusive application data public key 504 is used forthe decryption of the encrypted data according to the homomorphicencryption or the fully homomorphic encryption using the map companyexclusive application data secret key 503.

Only access rights and decrypting rights to the dynamic map data 1 aregranted to the map company exclusive application data management device12 regarding the map company exclusive application data public key 504.

Furthermore, all rights of access rights, decrypting rights and dataprocessing rights for the map company exclusive application data 2 aregranted to the map company exclusive application data management device12 regarding the map company exclusive application data public key 504.

Additionally, only access rights, decrypting rights and data processingrights for some type of data are granted to the automotive companyexclusive application data management device 13 regarding the mapcompany exclusive application data public key 504.

Here, regarding the map company exclusive application data public key504, the some type of data for which data processing rights to thedynamic map data 1 are granted is, for instance, positions of trafficlights, positions of signs and positions of road signs and the like.

Also, regarding the map company exclusive application data public key504, other type of data than the some type of data, for which the dataprocessing rights to the dynamic map data 1 is not granted is, forinstance, current sign information of traffic lights, legal displaycontents of signs and road signs, and the like.

Further, regarding the map company exclusive application data public key504, some type of data for which data processing rights to the mapcompany exclusive application data 2 are granted is, for instance,information on locations of shops, information on locations ofcommercial buildings and the like.

Furthermore, regarding the map company exclusive application data publickey 504, other type of data than the some type of data, for which thedata processing rights to the map company exclusive application data 2is not granted is, for instance, telephone numbers of shops, names ofcommercial building owners and the like.

Moreover, all rights of access rights, decrypting rights and dataprocessing rights for all types of data may be granted to the automotivecompany exclusive application data management device 13 regarding themap company exclusive application data public key 504.

Furthermore, the map company exclusive application data public key 504may be concurrently used as the dynamic map data public key 502 b. Inthis case, type of keys can be decreased equal to the number of thedynamic map data public key 502 b.

The automotive company exclusive application data secret key 505 is usedfor data encryption according to the homomorphic encryption or the fullyhomomorphic encryption. Regarding the automotive company exclusiveapplication data secret key 505, all rights of access rights, decryptingrights, and data processing rights are granted only to an operator ofthe automotive company exclusive application data management device 13.

The automotive company exclusive application data public key 506 is usedfor a decryption of encrypted data according to the homomorphicencryption or the fully homomorphic encryption.

Regarding the automotive company exclusive application data public key506, all rights of access rights, decrypting rights, data processingrights are granted only to an operator of the automotive companyexclusive application data management device 13.

An operator of the vehicle 15 is granted only access rights anddecrypting rights to the automotive company exclusive application datapublic key 506.

The dynamic map certification authority 112 delivers each of theplurality of secret keys generated and the plurality of public keys 150generated to a corresponding destination among the map company exclusiveapplication data management device 12 and the automotive companyexclusive application data management device 13 using encryptedcommunication via a communication network, while a security is beingmaintained.

The dynamic map data public key 502 a is delivered to, for instance, themap company exclusive application data management device 12, and thedynamic map data public key 502 b is delivered to, for instance, theautomotive company exclusive application data management device 13.

The map company exclusive application data secret key 503 is solelydelivered to, for instance, the map company exclusive application datamanagement device 12.

The map company exclusive application data public key 504 is deliveredto, for instance, the automotive company exclusive application datamanagement device 13.

The automotive company exclusive application data secret key 505 issolely delivered to, for instance, the automotive company exclusiveapplication data management device 13.

The automotive company exclusive application data public key 506 isdelivered to, for instance, the automotive company exclusive applicationdata management device 13 and the vehicle 15.

Further, the dynamic map certification authority 112 may encrypt theplurality of secret keys and the plurality of public keys 150 and storethem in electronic mediums such as a DVD-ROM, a BD-ROM or a USB memory.The electronic mediums such as the DVD-ROM, the BD-ROM or the USB memoryare preferably delivered to each of the map company exclusiveapplication data management device 12 and the automotive companyexclusive application data management device 13.

The dynamic map data output device 113 encrypts the dynamic map data 1generated by the dynamic map generating device 111 according to thehomomorphic encryption or the fully homomorphic encryption to generatethe encrypted data 100, using the dynamic map data secret key 501 whichis generated by the dynamic map certification authority 112.

The dynamic map data output device 113 outputs the encrypted data 100which is the encrypted dynamic map data 1 to each of the map companyexclusive application data management device 12 and the automotivecompany exclusive application data management device 13.

Moreover, the dynamic map data output device 113 may store the encrypteddata 100 which is the encrypted dynamic map data 1 in the electronicmediums such as a DVD-ROM, a BD-ROM, or a USB memory, and may deliverthe electronic mediums such as the DVD-ROM, the BD-ROM, or the USBmemory to each of the map company exclusive application data managementdevice 12 and the automotive company exclusive application datamanagement device 13.

FIG. 5 is a diagram illustrating a data processing flow by the mapcompany exclusive application data management device 12 and theautomotive company exclusive application data management device 13 inthe map information management system according to Embodiment 2. In FIG.5, the vehicle 15 is an automatic driving vehicle with a memory device,a car navigation device including a memory device and a map displaydevice, and the like.

In FIG. 5, the map company exclusive application data management device12 obtains the dynamic map data public key 502 a, and the map companyexclusive application data secret key 503 from the dynamic map datamanagement device 11 by encrypted communication via the communicationnetwork. The automotive company exclusive application data managementdevice 13 obtains the dynamic map data public key 502 b, the map companyexclusive application data public key 504, and the automotive companyexclusive application data secret key 505 from the dynamic map datamanagement device 11 by the encrypted communication via thecommunication network.

Furthermore, the map company exclusive application data managementdevice 12 and the automotive company exclusive application datamanagement device 13 individually receives the encrypted data 100 fromthe dynamic map data management device 11 by the encrypted communicationvia the communication network.

Note that the map company exclusive application data management device12 and the automotive company exclusive application data managementdevice 13 may receive the encrypted data 100 in a state that theencrypted data 100 is stored in the electronic mediums such as theDVD-ROM, the BD-ROM or the USB memory.

The map company exclusive application data management device 12 isgranted the dynamic map data public key 502 a, and the access right andthe decrypting right to the dynamic map data 1. However, the map companyexclusive application data management device 12 is not granted the rightto data-process the dynamic map data 1 using the dynamic map data publickey 502 a.

On the other hand, the automotive company exclusive application datamanagement device 13 is granted the dynamic map data public key 502 b,the access right and the decrypting right and the data processing rightto some type of data to the dynamic map data 1.

When acquiring the encrypted data 100 from the dynamic map datamanagement device 11, the map company exclusive application datamanagement device 12 generates the dynamic map data 205 which isdecrypted dynamic map data 1 based on the encrypted data 100 at the sametime as the acquisition, at the predetermined time intervals, or afterthe predetermined time has lapsed.

At this time, the map company exclusive application data managementdevice 12 decrypts the dynamic map data 1 as the dynamic map data 205according to the homomorphic encryption or the fully homomorphicencryption using the dynamic map data public key 502 a and verifies theauthenticity of the dynamic map data 1.

Thereby, the dynamic map data 1 decrypted as the dynamic map data 205 isverified whether it is legitimate (authentic) one received directly orindirectly from a legitimate generator, and if it is legitimate, it canbe confirmed to be authentic.

Moreover, since the map company exclusive application data managementdevice 12 is not granted the data processing right with regard to thedynamic map data public key 502 a, the map company exclusive applicationdata management device 12 cannot conduct data processing on the dynamicmap data 205, whereas the map company exclusive application datamanagement device 12 can browse the dynamic map data 205 to confirmwhether it is identical to the dynamic map data 1.

That is, an encryption is provided on the dynamic map data 205 in such away that data description contents of the dynamic map data 1 can be readbut data description contents of the dynamic map data 1 cannot bedata-processed.

After conducting an authenticity certification, the map companyexclusive application data management device 12 adds the map companyexclusive application data 2 to the dynamic map data 205 which isconfirmed (guaranteed) to be authentic. The map company exclusiveapplication data management device 12 encrypts data in which the mapcompany exclusive application data 2 is added to the dynamic map data205 according to the homomorphic encryption or the fully homomorphicencryption to generate the encrypted data 210, using the map companyexclusive application data secret key 503. The encrypted data 210 isoutput to the automotive company exclusive application data managementdevice 13.

Next, when acquiring the encrypted data 100 from the dynamic map datamanagement device 11, the automotive company exclusive application datamanagement device 13 generates the decrypted data 215 which is decrypteddynamic map data 1 based on the encrypted data 100 at the same time asthe acquisition, at the predetermined time intervals, or after thepredetermined time has lapsed.

At this time, the automotive company exclusive application datamanagement device 13 decrypts the decrypted data 215 from the encrypteddata 100 of the dynamic map data 1 according to the homomorphicencryption or the fully homomorphic encryption using the dynamic mapdata public key 502 b and verifies the authenticity of the dynamic mapdata 1.

Thereby, the dynamic map data 1 decrypted as the dynamic map data 205 isverified whether it is legitimate (authentic) one received directly orindirectly from a legitimate generator, and if it is legitimate, it canbe confirmed to be authentic.

Moreover, since the automotive company exclusive application datamanagement device 13 is not granted the data processing rights to alltypes of data with regard to the dynamic map data public key 502 b, theautomotive company exclusive application data management device 13cannot conduct data processing on the decrypted data 215, whereas theautomotive company exclusive application data management device 13 canbrowse the decrypted data 215 to confirm whether it is identical to thedynamic map data 1.

That is, an encryption is provided on the decrypted data 215 in such away that data description contents of the dynamic map data 1 can be readbut data description contents of the dynamic map data 1 cannot bedata-processed.

Further, when acquiring the encrypted data 210 from the map companyexclusive application data management device 12, the automotive companyexclusive application data management device 13 generates decrypted data225 which is individually decrypted dynamic map data 1 and decrypted mapcompany exclusive application data 2 based on the encrypted data 210 atthe same time as the acquisition, at the predetermined time intervals,or after the predetermined time has lapsed.

At this time, the automotive company exclusive application datamanagement device 13 generates the decrypted data 205 which is thedynamic map data 1 and the map company exclusive application data 2 thatare decrypted individually from the encrypted data of the dynamic mapdata 1 and the map company exclusive application data 2 according to thehomomorphic encryption or the fully homomorphic encryption using the mapcompany exclusive application data public key 504, and verifiesauthenticity of each of the dynamic map data 1 and the map companyexclusive application data 2.

Thereby, the dynamic map data and the map company exclusive applicationdata decrypted by decrypted data 225 are verified whether they arelegitimate (authentic) ones received directly or indirectly from alegitimate generator, and if they are legitimate, they can be confirmedto be authentic.

Since the automotive company exclusive application data managementdevice 13 is not granted the data processing rights to all types of datawith regard to the map company exclusive application data public key504, the automotive company exclusive application data management device13 can browse each of the dynamic map data 1 and the map companyexclusive application data 2 which are decrypted in the decrypted data225 to confirm whether they are identical to an original dynamic mapdata 1 generated by the dynamic map data management device 11 and anoriginal map company exclusive application data 2 generated by the mapcompany exclusive application data management device 12. However, theautomotive company exclusive application data management device 13cannot conduct data processing on the dynamic map data 1 and the mapcompany exclusive application data 2 which are decrypted in thedecrypted data 225.

That is, an encryption is provided on the decrypted data 225 in such away that data description contents of the dynamic map data 1 or the mapcompany exclusive application data 2 can be read but data descriptioncontents of the dynamic map data 1 or the map company exclusiveapplication data 2 cannot be data-processed, except for data descriptioncontents of some type of data.

After conducting an authenticity certification of decrypted data 215,the automotive company exclusive application data management device 13adds individually the automotive company exclusive application data 3 tothe decrypted data 215 which is confirmed (guaranteed) to be authentic.The automotive company exclusive application data management device 13encrypts data in which the automotive company exclusive application data3 is added to the decrypted data 215 according to the homomorphicencryption or the fully homomorphic encryption to generate the encrypteddata 220, using the automotive company exclusive application data secretkey 505. The automotive company exclusive application data managementdevice 13 outputs the generated encrypted data 220 to the vehicle 15.After acquiring the encrypted data 220, the vehicle 15 verifies theauthenticity of the dynamic map data 1 and the automotive companyexclusive application data 3 and decrypts them, using the automotivecompany exclusive application data public key 506.

Also, after conducting the authenticity certification of the decrypteddata 225, the automotive company exclusive application data managementdevice 13 outputs the encrypted data 210 before decryption, whichcorresponds to the decrypted data 225 which is confirmed (guaranteed) tobe authentic, to the vehicle 15. After acquiring the encrypted data 210,the vehicle 15 verifies the authenticity of the dynamic map data 1 andthe map company exclusive application data 2 and decrypts them, usingthe automotive company exclusive application data public key 506.

Moreover, after conducting an authenticity certification of decrypteddata 225, the automotive company exclusive application data managementdevice 13 adds individually the automotive company exclusive applicationdata 3 to the decrypted data 225 which is confirmed (guaranteed) to beauthentic. The automotive company exclusive application data managementdevice 13 encrypts data in which the automotive company exclusiveapplication data 3 is added to the decrypted data 225 according to thehomomorphic encryption or the fully homomorphic encryption to generatethe encrypted data 230, using the automotive company exclusiveapplication data secret key 505. The automotive company exclusiveapplication data management device 13 outputs the generated encrypteddata 230 to the vehicle 15. After acquiring the encrypted data 230, thevehicle 15 verifies the authenticity of the dynamic map data 1, the mapcompany exclusive application data 2, the automotive company exclusiveapplication data 3 and decrypts them, using the automotive companyexclusive application data public key 506.

Further, the automotive company exclusive application data secret key505 generating the encrypted data 220 and the automotive companyexclusive application data secret key 505 generating the encrypted data230 may be different keys.

As mentioned above, the map information delivery system according toEmbodiment 2 includes the dynamic map data management device 11 whichgenerates the encrypted data 100 based on the pre-generated dynamic mapdata 1, using the dynamic map data secret key 501 and outputs, the mapcompany exclusive application data management device 12 which obtainsthe encrypted data 100 from the dynamic map data management device 11,confirms authenticity of the dynamic map data 1 using the pre-receiveddynamic map data public key 502 a corresponding to the dynamic map datasecret key 501 and the encrypted data 100 obtained from the dynamic mapdata management device 11, generates the encrypted data 210 by thepre-received map company exclusive application data secret key 503,based on data in which the map company exclusive application data 2 isadded to the dynamic map data 1 which has been confirmed to beauthentic, and outputs the encrypted data 210, and the automotivecompany exclusive application data management device 13 which obtainsthe encrypted data 210 in which the map company exclusive applicationdata 2 is added to the dynamic map data 1 from the map company exclusiveapplication data management device 12, confirms the authenticity of thedata in which the map company exclusive application data 2 is added tothe dynamic map data 1, using the pre-received map company exclusiveapplication data public key 504 corresponding to the pre-received mapcompany exclusive application data secret key 503 and the encrypted data210, and generates the encrypted data 230 to be implemented in avehicle, by the pre-received automotive company exclusive applicationdata secret key 505, based on data in which the automotive companyexclusive application data 3 is further added to the data in which themap company exclusive application data 2 is added to the dynamic mapdata 1 which has been confirmed to be authentic.

Also, the dynamic map data management device 11 comprises the dynamicmap generating device 111 generating the dynamic map data 1, the dynamicmap certification authority 112 generating each of the dynamic map datasecret key 501 and the dynamic map data public key 502 a for decryptingthe encrypted data 100 by the dynamic map data secret key 501, the mapcompany exclusive application data secret key 503 and the map companyexclusive application data public key 504 for decrypting the encrypteddata 210 by the map company exclusive application data secret key 503,and the automotive company exclusive application data secret key 505 andthe automotive company exclusive application data public key 506 fordecrypting the encrypted data 230 by the automotive company exclusiveapplication data secret key 505, based on a predetermined access right,a predetermined decrypting right and a predetermined data processingright of each of the dynamic map data 1, the map company exclusiveapplication data 2, and the automotive company exclusive applicationdata 3, and distribute each generated secret key and each generatedpublic key, and the dynamic map data output device 113 generating theencrypted data 100 which is obtained by the homomorphic encryption orthe fully homomorphic encryption of the dynamic map data 1 using thegenerated dynamic map data secret key 501, and outputting. The dynamicmap certification authority 112 is preferably operated under a differentmanagement from those of the dynamic map generating device 111 and thedynamic map data output device 113.

Also, the map company exclusive application data management device 12obtaining the dynamic map data public key 502 a, the map companyexclusive application data secret key 503 and the encrypted data 100from the dynamic map data management device 11, decrypting the dynamicmap data 1 from the encrypted data 100, using the dynamic map datapublic key 502 a, and verifying authenticity of data, adding the mapcompany exclusive application data 2 to the obtained dynamic map data 1,generating the encrypted data 210 which is obtained by the homomorphicencryption or the fully homomorphic encryption of the dynamic map data 1and the map company exclusive application data 2 using the obtained mapcompany exclusive application data secret key 503, and outputting.

Also, the automotive company exclusive application data managementdevice 13 obtains the map company exclusive application data public key504 and the automotive company exclusive application data secret key 505from the dynamic map data management device 11, obtains the encrypteddata 210 from the map company exclusive application data managementdevice 12, decrypts the dynamic map data 1 and the map company exclusiveapplication data 2 from the encrypted data 210, using the map companyexclusive application data public key 504, verifies authenticity ofdata, adds the automotive company exclusive application data 3 to theobtained dynamic map data 1 and the map company exclusive applicationdata 2, generates the encrypted data 230 that is encrypted automotivecompany exclusive application data which is obtained by the homomorphicencryption or the fully homomorphic encryption of the dynamic map data1, the map company exclusive application data 2 and the automotivecompany exclusive application data 3 using the obtained automotivecompany exclusive application data secret key 505, and outputs.

By this way, when providing the map information including the dynamicmap data 1, the map company exclusive application data 2, the automotivecompany exclusive application data 3 and the like via a plurality oforganizations such as a map company and an automotive company insequence, the map information management system according to Embodiment2 prevents data alteration of the map information and confirmsauthenticity of the map information.

Also, in the map information management system according to Embodiment2, the encrypted dynamic map data 1 with the homomorphic encryption orthe fully homomorphic encryption is transmitted, for example, to the mapcompany exclusive application data management device 12 owned by the mapcompany or the automotive company exclusive application data managementdevice 13 owned by the automotive company. The map company exclusiveapplication data management device 12 or the automotive companyexclusive application data management device 13 receives the encrypteddynamic map data 1 and, can decrypted it with the public key owned byeach of them when having the decryption right. Further, when having thedata processing right, each of them can add the map company exclusiveapplication data 2 or the automotive company exclusive application data3 to the dynamic map data while it remains encrypted, using the publickey owned by each of them. The map company exclusive application datamanagement device 12 transmits the security protected encrypted data tothe automotive company exclusive application data management device 13.When the automotive company exclusive application data management device13 adds the automotive company exclusive application data 3, it canverify and decrypt using the owned public key in a case of having thedecrypting right, and adds the automotive company exclusive applicationdata 3 while the encrypted data remains encrypted using the owned publickey in a case of having the data processing right. Thereby, the securityprotected data can be stored in the automatic driving vehicle or thevehicle 15 such as a vehicle on which a car navigation is mounted, so asto prevent data alteration of map information including the dynamic mapdata 1.

REFERENCE SIGNS LIST

1, 205: dynamic map data; 2: map company exclusive application data; 3:automotive company exclusive application data; 10: external organizationdata management device; 11: dynamic map data management device; 12: mapcompany exclusive application data management device; 13: automotivecompany exclusive application data management device; 15: vehicle; 95:dynamic map data electronic signature; 100: encrypted data; 105: data;110: encrypted data; 111: dynamic map generating device; 112: dynamicmap certification authority; 113: dynamic map data output device; 114:map company exclusive application data electronic signature; 115, 125:combination data; 120: encrypted data; 121, 131: automotive companyexclusive application data electronic signature; 130: encrypted data;150: key; 210: encrypted data; 215, 225: decrypted data; 220: encrypteddata; 230: encrypted data; 501: dynamic map data secret key; 502, 502 a,502 b: dynamic map data public key; 503: map company exclusiveapplication data secret key; 504: map company exclusive application datapublic key; 505: automotive company exclusive application data secretkey; 506: automotive company exclusive application data public key

1-3. (canceled)
 4. A map information management system comprising: a mapinformation management device to generate encrypted data based on mapinformation, using a map information secret key, and output theencrypted data; a map company exclusive application data managementdevice to obtain the encrypted data from the map information managementdevice, confirm authenticity of the map information, using a mapinformation public key corresponding to the map information secret keyand the encrypted data obtained from the map information managementdevice, generate encrypted data by a map company exclusive applicationdata secret key, based on data which is obtained by adding map companyexclusive application data to the map information which has beenconfirmed to be authentic, and output the encrypted data.
 5. The mapinformation management system according to claim 4, further comprising:an automotive data management device to obtain the encrypted data whichis obtained by an encryption of the data which is obtained by adding themap company exclusive application data to the map information from themap company exclusive application data management device, confirmauthenticity of the data which is obtained by adding the map companyexclusive application data to the map information, using a map companyexclusive application data public key corresponding to the map companyexclusive application data secret key and the encrypted data obtainedfrom the map company exclusive application data management device,generate encrypted data by an automotive company exclusive applicationdata secret key, based on data which is further obtained by addingautomotive company exclusive application data to the data which isobtained by adding the map company exclusive application data to the mapinformation which has been confirmed to be authentic, and output theencrypted data.
 6. A map information management system comprising: a mapinformation management device including: a map information generatingdevice to generate map information; and a map information output deviceto generate a map information electronic signature for conducting anauthenticity certification of the map information, using the mapinformation secret key, based on the map information, and output the mapinformation and the map information electronic signature in combination,a map company exclusive application data management device to obtain themap information and the map information electronic signature from themap information management device, conduct a signature verification ofthe map information, using the map information public key correspondingto the map information secret key and the map information electronicsignature, add map company exclusive application data to the mapinformation which has been confirmed to be authentic by the signatureverification, generate a map company exclusive application dataelectronic signature for conducting an authenticity certification of themap information to which the map company exclusive application data hasbeen added, using a map company exclusive application data secret key,based on the map information to which the map company exclusiveapplication data has been added and the map information electronicsignature, and output the map information to which the map companyexclusive application data has been added, the map informationelectronic signature and the map company exclusive application dataelectronic signature in combination.
 7. The map information managementsystem according to claim 6, further comprising: an automotive datamanagement device to obtain the map information to which the map companyexclusive application data has been added, the map informationelectronic signature and the map company exclusive application dataelectronic signature from the map company exclusive application datamanagement device, conduct a signature verification of the mapinformation to which the map company exclusive application data has beenadded, using the map company exclusive application data public keycorresponding to the map company exclusive application data secret keyand the map company exclusive application data electronic signature, addautomotive company exclusive application data to the map information towhich the map company exclusive application data has been added, whichhas been confirmed to be authentic by the signature verification,generate an automotive company exclusive application data electronicsignature for conducting an authenticity certification of the mapinformation to which the automotive company exclusive application dataand the map company exclusive application data have been added, usingthe automotive company exclusive application data secret key, based onthe map information to which the automotive company exclusiveapplication data and the map company exclusive application data havebeen added and the map company exclusive application data electronicsignature, and output the map information to which the automotivecompany exclusive application data has been added, the map companyexclusive application data, the map information electronic signature andthe automotive company exclusive application data electronic signaturein combination.
 8. The map information management system according toclaim 7, wherein the map information management device includes a mapinformation certification authority to generate each of the mapinformation secret key and the map information public key for asignature verification of an electronic signature by the map informationsecret key, the map company exclusive application data secret key andthe map company exclusive application data public key for a signatureverification of an electronic signature by the map company exclusiveapplication data secret key, and the automotive company exclusiveapplication data secret key and an automotive company exclusiveapplication data public key for a signature verification of anelectronic signature by the automotive company exclusive applicationdata secret key, and distribute each generated secret key and eachgenerated public key.
 9. A map information management system comprising:a map information management device including: a map informationgenerating device to generate map information; and a map informationoutput device to generate encrypted map information which is obtained bya homomorphic encryption or a fully homomorphic encryption of the mapinformation using the map information secret key, and output theencrypted map information, a map company exclusive application datamanagement device to obtain the encrypted map information from the mapinformation management device, decrypt the encrypted map information toobtain the map information, using the map information public keycorresponding to the map information secret key, verify authenticity ofthe map information, add map company exclusive application data to theobtained map information, generate encrypted map company exclusiveapplication data which is obtained by the homomorphic encryption or thefully homomorphic encryption of the map information and the map companyexclusive application data using a map company exclusive applicationdata secret key, and output the encrypted map company exclusiveapplication data.
 10. The map information management system according toclaim 9, further comprising: an automotive data management device toobtain the encrypted map company exclusive application data from the mapcompany exclusive application data management device, decrypt theencrypted map company exclusive application data to obtain the mapinformation and the map company exclusive application data, using themap company exclusive application data public key corresponding to themap company exclusive application data secret key, verify authenticityof the map information and the map company exclusive application data,add the automotive company exclusive application data to the mapinformation and the map company exclusive application data, generateencrypted automotive company exclusive application data which isobtained by the homomorphic encryption or the fully homomorphicencryption of the map information, the map company exclusive applicationdata and the automotive company exclusive application data using theautomotive company exclusive application data secret key, and output theencrypted automotive company exclusive application data.
 11. The mapinformation management system according to claim 10, wherein the mapinformation management device includes a map information certificationauthority to generate each of the map information secret key and the mapinformation public key for decrypting encrypted data by the mapinformation secret key, the map company exclusive application datasecret key and the map company exclusive application data public key fordecrypting encrypted data by the map company exclusive application datasecret key, and the automotive company exclusive application data secretkey and an automotive company exclusive public key for decryptingencrypted data by the automotive company exclusive application datasecret key, based on a predetermined access right, a predetermineddecrypting right and a predetermined data processing right of each ofthe map information, the map company exclusive application data and theautomotive company exclusive application data, and distribute eachgenerated secret key and each generated public key.
 12. A mapinformation management device which generates encrypted data based onmap information, using a map information secret key, and outputs theencrypted data to a map company exclusive application data managementdevice, wherein the map company exclusive application data managementdevice obtains the encrypted data from the map information managementdevice, confirms authenticity of the map information, using a mapinformation public key corresponding to the map information secret keyand the encrypted data obtained from the map information managementdevice, and encrypts data which is obtained by adding map companyexclusive application data to the map information which has beenconfirmed to be authentic, by a map company exclusive application datasecret key.
 13. A map company exclusive application data managementdevice which obtains encrypted data from a map information managementdevice being adapted to generate the encrypted data based on mapinformation using a map information secret key, confirms authenticity ofthe map information, using a map information public key corresponding tothe map information secret key and the encrypted data obtained from themap information management device, generates encrypted data by a mapcompany exclusive application data secret key, based on data which isobtained by adding map company exclusive application data to the mapinformation which has been confirmed to be authentic, and outputs theencrypted data.
 14. A automotive data management device which: obtainsencrypted data encrypted from data which is obtained by adding mapcompany exclusive application data to map information from a map companyexclusive application data management device; the map company exclusiveapplication data management device being adapted to obtain the encrypteddata from a map information management device, the map informationmanagement device being adapted to generate the encrypted data based onthe map information using a map information secret key, the map companyexclusive application data management device being adapted to confirmauthenticity of the map information, using a map information public keycorresponding to the map information secret key and the encrypted dataobtained from the map information management device, generate theencrypted data, using a map company exclusive application data secretkey, based on data which is obtained by adding the map company exclusiveapplication data to the map information which is confirmed to beauthentic, and output the encrypted data, confirms authenticity of thedata which is obtained by adding the map company exclusive applicationdata to the map information, using a map company exclusive applicationdata public key corresponding to the map company exclusive applicationdata secret key and the encrypted data obtained from the map companyexclusive application data management device; generates encrypted databy an automotive company exclusive application data secret key, based ondata which is obtained by further adding automotive company exclusiveapplication data to the data which has been obtained by adding the mapcompany exclusive application data to the map information which has beenconfirmed to be authentic; and outputs the encrypted data.
 15. A mapinformation management device including a map information generatingdevice to generate map information, and a map information output deviceto generate a map information electronic signature for conducting anauthenticity certification of the map information, using a mapinformation secret key, based on the map information, wherein the mapinformation output device outputs the map information and the mapinformation electronic signature in combination to a map companyexclusive application data management device, and wherein the mapcompany exclusive application data management device obtains the mapinformation and the map information electronic signature from the mapinformation management device, conducts a signature verification of themap information, using a map information public key corresponding to themap information secret key and the map information electronic signature,adds map company exclusive application data to the map information whichhas been confirmed to be authentic by the signature verification, andgenerates a map company exclusive application data electronic signaturefor conducting an authenticity certification of the map information towhich the map company exclusive application data has been added, using amap company exclusive application data secret key, based on the mapinformation to which the map company exclusive application data has beenadded and the map information electronic signature.
 16. The mapinformation management device according to claim 15, including a mapinformation certification authority to generate each of the mapinformation secret key and the map information public key for asignature verification of an electronic signature by the map informationsecret key, and the map company exclusive application data secret keyand a map company exclusive application data public key for a signatureverification of an electronic signature by the map company exclusiveapplication data secret key, and distribute each generated secret keyand each generated public key.
 17. A map company exclusive applicationdata management device which: obtains a map information and a mapinformation electronic signature from a map information managementdevice being adapted to generate the map information electronicsignature for conducting an authenticity certification of the mapinformation, using a map information secret key; conducts a signatureverification of the map information, using a map information public keycorresponding to the map information secret key and the map informationelectronic signature; adds map company exclusive application data to themap information which has been confirmed to be authentic by thesignature verification; generates a map company exclusive applicationdata electronic signature for conducting an authenticity certificationof the map information to which the map company exclusive applicationdata has been added, using a map company exclusive application datasecret key, based on the map information to which the map companyexclusive application data has been added and the map informationelectronic signature; and outputs the map information to which the mapcompany exclusive application data has been added, the map informationelectronic signature and the map company exclusive application dataelectronic signature in combination.
 18. An automotive data managementdevice which: obtains map information to which map company exclusiveapplication data has been added, a map information electronic signatureand a map company exclusive application data electronic signature from amap company exclusive application data management device, the mapcompany exclusive application data management device being adapted toobtain the map information and the map information electronic signaturefrom a map information management device, the map information managementdevice being adapted to generate the map information electronicsignature for conducting an authenticity certification of the mapinformation, using a map information secret key, the map companyexclusive application data management device being adapted to conduct asignature verification of the map information, using a map informationpublic key corresponding to the map information secret key and the mapinformation electronic signature, add the map company exclusiveapplication data to the map information which has been confirmed to beauthentic by the signature verification, and generate a map companyexclusive application data electronic signature for conducting anauthenticity certification of the map information to which the mapcompany exclusive application data has been added, using a map companyexclusive application data secret key, based on the map information towhich the map company exclusive application data has been added and themap information electronic signature; conducts a signature verificationof the map information to which the map company exclusive applicationdata has been added, using a map company exclusive application datapublic key corresponding to the map company exclusive application datasecret key and the map company exclusive application data electronicsignature; adds automotive company exclusive application data to the mapinformation to which the map company exclusive application data whichhas been confirmed to be authentic by the signature verification hasbeen added; generates an automotive company exclusive application dataelectronic signature for conducting an authenticity certification of themap information to which the automotive company exclusive applicationdata and the map company exclusive application data have been added,using an automotive company exclusive application data secret key, basedon the map information to which the automotive company exclusiveapplication data and the map company exclusive application data havebeen added and the map company exclusive application data electronicsignature; and outputs the map information to which the automotivecompany exclusive application data has been added, the map companyexclusive application data, the map information electronic signature andthe automotive company exclusive application data electronic signaturein combination.
 19. A map information management device including a mapinformation generating device to generate map information, and a mapinformation output device to generate encrypted map information which isobtained by a homomorphic encryption or a fully homomorphic encryptionof the map information using a map information secret key, wherein themap information output device outputs the generated encrypted mapinformation to a map company exclusive application data managementdevice, and wherein the map company exclusive application datamanagement device obtains the encrypted map information from the mapinformation management device, decrypts the encrypted map information toobtain the map information, using a map information public keycorresponding to the map information secret key, verifies authenticityof the map information, adds map company exclusive application data tothe obtained map information, and generates encrypted map companyexclusive application data which is obtained by the homomorphicencryption or the fully homomorphic encryption of the map informationand the map company exclusive application data using a map companyexclusive application data secret key.
 20. The map informationmanagement device according to claim 19, comprising a map informationcertification authority to generate each of the map information secretkey and the map information public key for decrypting encrypted data bythe map information secret key, and the map company exclusiveapplication data secret key and a map company exclusive application datapublic key for decrypting encrypted data by the map company exclusiveapplication data secret key, based on a predetermined access right, apredetermined decrypting right and a predetermined data processing rightof each of the map information and the map company exclusive applicationdata, and distribute each generated secret key and each generated publickey.
 21. A map company exclusive application data management devicewhich: obtains encrypted map information from a map informationmanagement device being adapted to generate the encrypted mapinformation which is obtained by a homomorphic encryption or a fullyhomomorphic encryption of map information using a map information secretkey; decrypts the encrypted map information to obtain the mapinformation, using a map information public key corresponding to the mapinformation secret key; verifies authenticity of the map information,adds map company exclusive application data to the obtained mapinformation; generates encrypted map company exclusive application datawhich is obtained by the homomorphic encryption or the fully homomorphicencryption of the map information and the map company exclusiveapplication data using a map company exclusive application data secretkey; and outputs the encrypted map company exclusive application data.22. An automotive data management device which: obtains encrypted mapcompany exclusive application data from a map company exclusiveapplication data management device, the map company exclusiveapplication data management device being adapted to obtain encrypted mapinformation which is obtained by a homomorphic encryption or a fullyhomomorphic encryption of map information using a map information secretkey, decrypt the encrypted map information to obtain the mapinformation, using a map information public key corresponding to the mapinformation secret key, verify authenticity of the map information, addmap company exclusive application data to the obtained map information,and generate the encrypted map company exclusive application data whichis obtained by the homomorphic encryption or the fully homomorphicencryption of the map information and the map company exclusiveapplication data using a map company exclusive application data secretkey; decrypts the encrypted map company exclusive application data toobtain the map information and the map company exclusive applicationdata, using a map company exclusive application data public keycorresponding to the map company exclusive application data secret key;verifies authenticity of the map information and the map companyexclusive application data; adds automotive company exclusiveapplication data to the map information and the map company exclusiveapplication data; generates encrypted automotive company exclusiveapplication data which is obtained by the homomorphic encryption or thefully homomorphic encryption of the map information, the map companyexclusive application data and the automotive company exclusiveapplication data using a map company exclusive application data secretkey; and outputs the encrypted automotive company exclusive applicationdata.